wipa.org

.org crawl

First seen 2026-04-15 · Last seen 2026-05-18 · ok HTTP/1.1 200 7095 ms crawled 2026-05-10

US · 8.29.155.129 · AS36444 Liquid Web, L.L.C

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
WIPA - Wedding Industry Professionals Association
Language
en-US
Generator
Site Kit by Google 1.171.0
Canonical
https://www.wipa.org/
Feeds

Open Graph

url
https://www.wipa.org/
title
WIPA - Wedding Industry Professionals Association
locale
en_US
site name
WIPA

Technology

Server
nginx
CMS
WordPress
Analytics
  • Google Tag Manager
Fonts
  • Font Awesome
  • Google Fonts

Third-party hosts loaded (4)

  • fonts.googleapis.com×5
  • use.fontawesome.com×4
  • cdn.jsdelivr.net×3
  • www.googletagmanager.com×2

Social

Registration

Registrar
GoDaddy.com, LLC
Created
2012-05-30
Expires
2026-05-30 10 days left
Updated
2025-07-14
Name servers
  • ns49.domaincontrol.com
  • ns50.domaincontrol.com

DNS records live

NS
  • ns49.domaincontrol.com
  • ns50.domaincontrol.com
MX
  • 0 wipa-org.mail.protection.outlook.com
TXT
  • NETORG17432594.onmicrosoft.com
  • MS=ms66183322

Email authentication partial

SPF
v=spf1 include:_spf-usg1.ppe-hosted.com include:spf.US.exclaimer.net include:secureserver.net include:arcstonespf.smtp.com ~all
softfail (~all)
DMARC
v=DMARC1;p=none;pct=100;rua=mailto:nwadmin@wipa.org;ruf=mailto:info@wipa.org;ri=86400;fo=1;
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-04-07 to 2026-07-06
Expires in 47 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.wipa.org/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • weak frame protection
  • weak content type protection
Header values
referrer-policy
strict-origin-when-cross-origin, strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN, SAMEORIGIN
permissions-policy
accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(self), encrypted-media=(), fullscreen=*, geolocation=(self), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=*, picture-in-picture=*, publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=*, usb=(), xr-spatial-tracking=(), gamepad=(), serial=(), private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(self), encrypted-media=(), fullscreen=*, geolocation=(self), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=*, picture-in-picture=*, publickey-credentials-get=(), screen
x-content-type-options
nosniff, nosniff
content-security-policy
default-src * data: blob: 'unsafe-inline' 'unsafe-eval';, upgrade-insecure-requests;
strict-transport-security
max-age=63072000, max-age=63072000
cross-origin-opener-policy
unsafe-none, unsafe-none
cross-origin-embedder-policy
unsafe-none; report-to='default', unsafe-none; report-to='default'
cross-origin-resource-policy
cross-origin, cross-origin

Links to (5)

Linked from (3)